Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,395 CVEs tagged with CWE-522217 Critical, 485 High, 646 Medium, 45 Low, 2 Unrated.

CVE-2019-3947

Published Jun 12, 2019

Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project file can recover the database cre…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-6567

Published Jun 12, 2019

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants…

CVSS 5.5 · Medium

CVE-2019-11367

Published Jun 3, 2019

An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password in the WWW-Authenticate attrib…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10329

Published May 31, 2019

Jenkins InfluxDB Plugin 1.21 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12452

Published May 29, 2019

types/types.go in Containous Traefik 1.7.x through 1.7.11, when the --api flag is used and the API is publicly reachable and exposed without sufficient access control (which is co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4138

Published May 29, 2019

IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict T…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5627

Published May 22, 2019

The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encoded strings, i.e. clear text. These persist in the cache eve…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5626

Published May 22, 2019

The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This file persists until the user logs out or the session times…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5625

Published May 22, 2019

The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of th…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10139

Published May 17, 2019

During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXXXXXX.var` which contains the a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8350

Published May 13, 2019

The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an information disclosure vulnerability that leaked the user's password…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,126-1,150 of 1,395 CVEsPage 46 of 56